Apusthemes develops WordPress themes and plugins including Superio, CareerUp, and WP Private Messaging, presenting a narrow but web-facing attack surface centered on theme and plugin functionality. Its disclosed vulnerabilities cluster around input-handling and access-control issues, notably cross-site scripting, privilege assignment, and authorization weaknesses that are characteristic of WordPress theme and plugin implementations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apusthemes over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-12213CRITICAL The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin allowing a user to supply the 'role' field w | Feb 12, 2025 | 9.8 | 28 | NO | NO |
CVE-2024-12296HIGH The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'import_pa | Feb 12, 2025 | 8.8 | 24 | NO | NO |
CVE-2022-4114MEDIUM The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as a subscriber to perform Cross-Site Scripting attacks. | Jan 2, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-0453MEDIUM The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user m | Feb 21, 2023 | 4.3 | 17 | NO | NO |
CVE-2022-1167MEDIUM There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme before 2.3.1, via the filter parameters. | Apr 4, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apusthemes.
Media articles that mention a CVE ID that affects a product developed by Apusthemes — matched by CVE ID, not by vendor name.